Post

Secure Inputs and Secure Outputs: What They Actually Protect

Diesen Beitrag auf Deutsch lesen

A per-action toggle in Power Automate that masks credentials and personal data in run history and logs, without changing how the action executes.

TL;DR

Toggle Secure Inputs and Secure Outputs independently per action in a flow’s settings to mask passwords, tokens and personal data in run history and logs, showing “content hidden” instead of plain text — the toggle only changes what gets logged, not how the action executes, so there’s no meaningful performance cost.

Original by Marcel Lehmann, on PowerPlatformTip. Read the original

This is our own summary, not a republication or full translation. Both publications are edited by Marcel Lehmann.

Governance takeaway

  • Makers: flip the toggle on for every action that touches a password, token, or personal data — it costs one setting change and nothing in performance.
  • Security/Compliance: treat it as a logging control only — it hides values from run history, not from how the flow actually handles that data, so it never replaces DLP policies or access reviews.
  • Admins/CoE: add it as a one-line item in flow review checklists, since there’s no tradeoff to weigh before requiring it.
This post is licensed under CC BY 4.0 by the author.